content/en/news/releases/1.6.x/announcing-1.6.5/index.md
This release fixes the security vulnerability described in our July 9th, 2020 news post.
This release contains bug fixes to improve robustness. These release notes describe what’s different between Istio 1.6.5 and Istio 1.6.4.
{{< relnote >}}
*.example.com, Envoy incorrectly allows nested.subdomain.example.com, when it should only allow subdomain.example.com.
istioctl validate to disallow unknown fields not included in the Open API specification (Issue 24860)stsPort to sts_port in Envoy's bootstrap file.targetUri to stackdriver_grpc_service.status.sidecar.istio.io/port to zero (Issue 24722)k8s.overlays on BaseComponentSpec. (Issue 24476)istio-agent to create elliptical curve CSRs when ECC_SIGNATURE_ALGORITHM is set.scaleTargetRef naming in HorizontalPodAutoscaler for Istiod (Issue 24809)